The London office where swinging pendulums keep cyber threats at bay
ianvisits.co.uk
ianvisits.co.uk
Fun fact, HN itself was "hacked" due to bad random once (https://news.ycombinator.com/item?id=639976).
It is quite a leap to say "timestamp-based seeds are insecure, let's upgrade to lava lamps".
The digit chance is easy:
For a single digit to appear one needs 1/3 * 1/10 = 1/30.
For a single letter to appear one needs 1/3 * 1/26 = 1/78.
But the bits of entropy throw me off. 26 + 26 + 10 = 62, which is 2^5.954. But that is for a uniform distribution. The writer states that it actually is 2^5.826, or 1/~56.7. I don't get how they to that number.
Like you said, the probability of any digit appearing is 1/30, and there are 10 digits. The probability of a lower- or upper- case letter appearing is 1/78, and there are 26+26 = 52 letters.
Plugging that into the formula for Shannon entropy, we get this:
- 10 * (1/30) * log_2(1/30) - 52 * (1/78) * log_2(1/78) =~ 5.826
For example this has passed NIST SP800-22 and SP800-90B [1].
As far as I can tell, cloudflares DIY lamps/pendulums are not NIST certified.
[1] https://www.idquantique.com/random-number-generation/product...
Some would claim that CMVP, FIPS 140-3, Common Criteria stickers on a black box (HSM) is security theater.
They do, don't they? I think the Lavalamps, etc, are just _extra_ entropy. The more entropy you add (even if it's _not_ a certified or perfect random source) only improves the random number generator.
jk.
That makes them by definition worse than the OpenSSL version that leaked user keys on request. /s
Like all the COVID-prevention theatre: sitting in restaurants and only masking when you visit the toilet. Hand-washing often whilst in unventilated areas with no masks. That's all "COVID theatre" IMO, as it fails to actually prevent the thing ostensibly being tackled.
My favourite one FWIW was wiping down the seat padding in the gym where nobody was masked - I mean who came up with that??
A creative hardware source of legit randomness is not the same as security theatre, and arguably has some useful educational aspect - it's certainly a talking point!
COVID aside, isn't wiping down gym equipment after use just good sanitary practice? I don't want to slide in on someone else's greasy residue.
Yes it is much more cool to look at than a zener diode, but it is still a source of physical entropy. And one could argue that a whole bunch of chaotic pendulums are more resilient to failure than a single diode.
https://www.youtube.com/watch?v=1cUUfMeOijg
(Mention of the London pendulums at 2:39)
Method for seeding a pseudo-random number generator with a cryptographic hash of a digitization of a chaotic system
> A method for generating a pseudo-random numbers Initially, the state of a chaotic system is digitized to form a binary string. This binary string is then hashed to produce a second binary string. It is this second binary string which is used to seed a pseudo-random number generator. The output from the pseudo-random number generator may be used in forming a password or cryptographic key for use in a security system.
* https://patents.google.com/patent/US5732138A/en
Originally filed by SGI in 1996.
See also:
* https://en.wikipedia.org/wiki/Lavarand
* https://www.cloudflare.com/en-ca/learning/ssl/lava-lamp-encr...
That sentence triggers me on so many levels. Down below in the article it says that cameras are sampling the motion. So, ultimately the setup is connected to something, and it is being actively used as a quality source of entropy for cryptography. Brilliant, actually, but this is not what "keeps the internet safe". Strong encryption is a source of trust, nothing more. Proper security needs to rely on a few things that we have to assume to be unbreakable. Only then we can build on top of that. Sadly, even unbreakable encryption, if used incorrectly, can bring the whole thing down. I really don´t like articles that sensationalize "neat details" and by that distort the bigger picture.
Btw, I imagine a camera pointed at a busy intersection with lots of pedestrian traffic (e.g. Times Square) to generate much more entropy.
Question : With respect to breaking cryptography, today's cryptographically secure pseudo random number generators (CSPRNGs) seem capable. What threat scenarios would require true (or near-true) random generators?
Another benefit of a CSPRNG is vastly higher performance than most TRNGs can achieve. A TRNG often provide kbps birate. A CSPRNG can easily deliver Many MBps, even GBps.
Wouldn't that result in time based patterns matching the daytime/nighttime cycle? Then again, I guess this would only happen during continuous use over a number of days and perhaps that's not the use case.
Also, it's obviously a stunt - you are probably much better off measuring decay of trace amounts of natural radioactive isotopes. But it is not without merit.
Which is precisely what CF does in their Singapore office.
The same could be achieved electronically with a simple circuit inside their servers, but it wouldn't look quite as good.
Also, somewhere in the thread, they mention that it is probably too hard to verify how it is actually implemented in the hardware.
https://www.reddit.com/r/crypto/comments/klcx4p/is_true_rand...
I guess in security only the paranoid prevails...
Or it is indeed just a cool gimmick...
But it is also a source of entropy that is hard to manipulate (if we ignore the cameras, image generation etc). And it is a good source, initiator for discussions about entropy, random numbers and why we need them to secure things. This thread on HN shows that it is so. And for 'normal' people probably even more.
I'm sure they have a lot of non-geeky visitors that look at the installation, read the sign and start asking questions. And if it was me, starting to jump in front of the installation, waving my arms - to provide my bit of entropy to the pool.
Here is an explanation of what was possible when a Debian packager mistakenly introduced a patch which reduced the SSL certificate keyspace in 2008: https://jblevins.org/log/ssh-vulnkey
The possibilities of keys which were generated by this random number generator was so small, that a brute-force attack on keys was feasible.
That being said, for years, random number generators have been using random signals coming to your computer (key strokes, network packets, ...) and feeding them into a sponge function. You don't need lava lamps or pendulums to generate random numbers, it's just for the press.
If implemented in full tool assisted speedruns, this can become entirely ridiculous. That rare thing you need to grind hours to find? nope. just press these 18 buttons starting at the right frame and it'll drop first try.
If you have something that's geared towards speed running, fast execution and mastering, being deterministic is actually a good thing. Otherwise, the player has to re-roll a hundred times to get the "good seed" to get a good run - that's very frustrating. Look at some of the kings quest speedruns for this kinda frustration.
Or in a similar direction - tetris with a true random piece selection can result in very frustrating and unwinnable piece sequences (which bastard tetris is dialing to 12). Instead, quite a few modern implementations choose some set of tetrimonios and fill a bag with 3-5 repetitions of this set and choose from that. This limits the possibility and length of possibly frustrating pieces.
At a GDQ it's fun to watch some awful exploit "win" Mario in eight seconds (not a real example) by messing with a game bug and precise input, but it's also fun to watch somebody who is incredibly good beat it the way you'd imagine you could if you were much better at the game, so there's room for multiple categories in popular games.
If there's a split it can often be resolved by having two categories. If you think it's stupid to hope to get a good seed in Minecraft, you can just only run the chosen seed categories, meanwhile if you think that sucks because it doesn't reward agile thinking you might prefer the random only categories. Both groups get to have fun.
Each has to be secure with a unique unpredictable element.
One way (of many) is to use complex PRNG's - Psuedo Random Number Generators, but these can (theorectically) be sequence guessed and then are predictable (or least have a greatly reduced "guess space").
A hybrid way is to regularly reseed a PRNG with a "truly random" starting point, milk that for a few hundred values, and then kick it again with a new random seed.
These particular pendulums have "simple" mechanics that are similar to the dynamic systems represented by Lorenz's Butterfly [1] (not exactly but with similar properties) and thus move in chaotic unpredicable ways (such as the timing between the last crossbar changing directions) - these can be "driven" (the base rocked | vibrated) by a small motor) so they continuusly move and yet the path through phase space is still unpredictable.
So, without knowing for certain whether this is what Cloudflare is doing here, that is one way in which many many truly random numbers can be generated to feed into secure handshakes; using unpredictable seeds to feed into twisted PRNGs.
If you can guess how the random key is generated, then you can decrypt the message without breaking either encryption algorithm. That's why it is important to have really unpredictable random data, and physical randomness is the best for that.
In practice, that wall of pendulums is unlikely to make a difference compared to the more mundane techniques used in most computers these days, that rely on some CSPRNG combined with various hard to predict system events (ex: interrupt timing), but it looks way cooler.
How random are the pendulums and how are they powered? Pendulums are usually quite predictable. Or are these double pendulums?
They add randomness by adding daylight. Could you use this for an attack (say, shining light from the outside during the night)?
"critical to the security of the global internet"? Really?
OTOH...if I ran Cloudflare's PR Dept., and was responsible for keeping the internet's millions of self-styled experts (who generally know just enough to be really annoying) feeling both informed, and sure of Cloudflare's security virtues - then I'd probably be pushing for more of these setups. And for-sure one of 'em in any Cloudflare office where I or my people might be stuck giving interviews to journalists. Every second of an X-minute interview that was "wasted" by the reporter staring at the Sock Puppets of Randomness would be one happier second in the lives of me and my people...
/s?